CVE-2013-0310

Priority
Medium
Description
The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel
before 3.4.8 allows local users to cause a denial of service (NULL pointer
dereference and system crash) or possibly have unspecified other impact via
an IPOPT_CIPSO IP_OPTIONS setsockopt system call.
Ubuntu-Description
A flaw was found in Linux kernel's validation of CIPSO (Common IP Security
Option) options set from userspace. A local user that can set a socket's
CIPSO options could exploit this flaw to cause a denial of service (crash
the system).
References
Bugs
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-1608.12)
Ubuntu 12.10 (Quantal Quetzal):not-affected (3.5.0-1600.1)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-350.56)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):released (3.0.0-25.41~lucid1)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (abandoned)
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):pending (3.5.0-6.6~precise1)
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Patches:
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Source: linux (LP Ubuntu Debian)
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-45.99)
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-31.49)
Ubuntu 12.10 (Quantal Quetzal):pending (3.5.0-6.6)
Ubuntu 13.04 (Raring Ringtail):not-affected (3.7.0-0.1)
Ubuntu 13.10 (Saucy Salamander):not-affected (3.7.0-0.1)
Patches:
Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2Fixed by 89d7ae34cdda4195809a5a987f697a517a2a3177
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-1419.26)
Ubuntu 12.10 (Quantal Quetzal):pending (3.5.0-207.13)
Ubuntu 13.04 (Raring Ringtail):not-affected (3.5.0-207.13)
Ubuntu 13.10 (Saucy Salamander):not-affected (3.5.0-207.13)
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life, does not affect buildd)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):not-affected
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2013-05-10 19:14:42 UTC (commit 6828)